Staff, Security Engineer
Indexed description
Job Overview
The Staff, Vulnerability Engineer is a specialist in Penetration Testing and Information Security Vulnerability Management. This hands-on role involves conducting penetration tests and vulnerability assessments on complex applications, operating systems, and wired and wireless networks. In response to an ever-changing threat landscape, they establish a proactive program to assess Macy’s resilience against real-world tactics, techniques, and procedures (TTPs).
What You Will Do
- Establish a risk-based approach for evaluating and prioritizing new and emerging threats.
- Stay current on emerging technology trends and the threat landscape, providing subject matter knowledge on specific adversarial threats and risks to assist with mitigation strategies.
- Design, coordinate, and lead simulations based on organizationally defined threat scenarios.
- Participate in reviewing and developing security strategies, best practices, policies, and procedures.
- Provide leadership, share knowledge, and mentor team members.
- Build working relationships with Macy’s TMRC, leadership, and third parties to identify top threats.
- Develop standard Rules of Engagement for real-time testing.
- Document detailed findings, analysis, and recommendations.
Skills You Will Need
- AI & Machine Learning: Expertise in Generative AI, LLMs, RAG, AI Agents, Prompt Engineering, LangChain/LangGraph, anomaly detection, NLP, transformers, and security-focused ML solutions.
- Security Engineering: Strong experience in detection engineering, threat hunting, SIEM/XDR/EDR, MITRE ATT&CK, Sigma, OCSF, threat intelligence, and enterprise security operations.
- Cloud & Infrastructure: Advanced knowledge of AWS, Azure, GCP, Databricks, Kubernetes, Docker, CI/CD, and scalable cloud-native security architectures.
- Software Development: Strong programming skills in Python, SQL, JavaScript, C/C++, API development, automation, and distributed systems engineering.
- Threat Protection: Experience protecting large enterprise environments through advanced analytics, behavioral detection, adversary simulation, and AI-powered security automation.
- Research & Innovation: Proven track record of cybersecurity research, patents, publications, and development of innovative security technologies.
- Leadership & Collaboration: Ability to lead cross-functional initiatives, influence architecture decisions, mentor engineers, and partner effectively across security and engineering organizations.
- Communication: Excellent written, verbal, and presentation skills, with experience communicating technical concepts to executive and technical audiences.
- Education/Certifications: PhD or Master's degree in a technical discipline preferred; AI, Cloud, or Cybersecurity certifications are a plus.
- Experience: 10+ years of experience in software engineering, cybersecurity, AI/ML, or related fields with production-scale deployments.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search